Thursday, January 17, 2019

Question regarding ASA Cryptomaps

We have an external company we have a S2S vpn with and they have announced they are changing over to a new ISP with a new public IP block assigned to them by ARIN. Because of this, I have been advised to add new peer addresse to our VPN configuration but keep the remaining peers in the configuration. Because of this, I thought it might be better to add a whole new connection profile with the new peer IP address and new cryptomaps for the new public ip addresses that will reference public facing servers.

My question is the following:

  • 1. Can I add a new connection profile in the ASA and new cryptomaps for this profile without it interfering with the existing S2S connection that we are utilizing now?

The reason I ask this is to be prepared for the cut over but I don't want to add anything to the running config until I know for sure it won't interfere with our existing S2S connection.

EDIT: Sorry, I realize my title doesn't line up with my question.



No comments:

Post a Comment